The risk then creates the following registry entry so that it is executed every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Sys_Kl" = "C:\Archivos de Programa\Sys_Kl\sys_kl.exe 1"